ZeroHour

CVE-2013-3346

KEVmass

Memory Corruption RCE in Adobe Reader and Acrobat

CISA: Adobe Reader and Acrobat Memory Corruption Vulnerability

CVSS
EPSS
79%p100
Published
KEV added
AI analysis

Adobe Reader and Acrobat contain a memory corruption vulnerability (CWE-119, buffer/pointer handling error) that can allow an attacker to execute arbitrary code or crash the application. The bug is triggered by processing maliciously crafted content, typically when a user opens a booby-trapped PDF document. Successful exploitation yields arbitrary code execution with the privileges of the logged-in user, while failed exploitation can cause a denial of service. Anyone running affected Adobe Reader or Acrobat installations is exposed, with desktop users who open PDFs from email or the web at greatest risk. The flaw has been exploited in the wild: CISA added it to the KEV catalog on 2022-03-03 and it carries a very high EPSS score of 78.6%, although no public proof-of-concept is known.

What to do: Apply vendor-supplied updates to Adobe Reader and Acrobat immediately, per the Adobe security bulletin and the CISA KEV required action, and retire or upgrade legacy unpatched builds that are past end of support. Because exploitation requires a user to open a crafted PDF, inspect or sandbox PDFs at email and web gateways and hunt for signs of PDF exploit delivery; treat this flaw as actively exploited given the KEV listing and 78.6% EPSS.

Affected
Adobe Reader
Adobe Acrobat
Estimated exposure
massorder of 100M+ users at time of disclosure (Adobe Reader was then the dominant PDF reader); residual unpatched legacy deployments likely still in the millions — Estimated from Adobe Reader/Acrobat's near-universal presence on enterprise and consumer desktops when the flaw was disclosed; exact install counts are not in the data, so treat this as an order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.

CISA Known Exploited Vulnerability
Affected
Adobe Reader and Acrobat
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
Reader and Acrobat
Weakness
CWE-119

In the news